SysOpt Forums

System Optimization and PC Performance

[ Home | News | Features | User Reviews | Overclocking | Benchmarks | About Us | Forum FAQ

Go Back   SysOpt Forums > General Tech > General Tech Discussion

General Tech Discussion Any TECHNICAL discussion not covered in the topics below.

Reply
 
Thread Tools Search this Thread Display Modes
Old 05-22-2000, 03:31 PM   #1
Gene C.
Senior Member
 
Join Date: Aug 1999
Location: Amelia Island/Fernandina Beach, Fl. U.S.
Posts: 962
Exclamation upcomeing KAK html virus

I copied this from a security e-mail I get. I don't know how they got there info. on it, but thought I would pass it alone. these things are so common now days.
Kinda makes you feel bad if you don't get one.

Because of the timing of these newsletters, I was way behind
the curve to get a newsletter out on the ILOVEYOU virus, but
here's a heads up for the next one:

It's called KAK. It works a great deal like the Love Bug except,
unlike most e-mail viruses, this pup preys on e-mail programs
that understand HTML. You needn't click on anything once you
open the e-mail message - just opening the message is enough
to trigger the virus. Gosh. Computers running Internet
Explorer 5.0 or Microsoft Office 2000 are most at risk because
the virus uses a wormhole found in the program's ActiveX control
called scriptlet.typelib. No word yet on a subject message to
look out for.

will post as soon as I hear something new.
Gene C. is offline   Reply With Quote
Old 05-22-2000, 03:55 PM   #2
SoopaStar
Ultimate Member
 
SoopaStar's Avatar
 
Join Date: May 1999
Location: Cincinnati, OH
Posts: 1,431
Lightbulb

Actually, (and i could br wrong) but i think Kak is an old one...
http://www.symantec.com/avcenter/ven...t.kakworm.html
And it only infects Outlook Express users (outlook too, maybe) using the signature feature.
Paul
SoopaStar is offline   Reply With Quote
Old 05-22-2000, 04:23 PM   #3
psyklone
Senior Member
 
Join Date: Aug 1999
Location: Dallas, Tx. US
Posts: 851
Lightbulb

yup the kakworm is an old one. it's a tricky one because it will embed itself in an HTML email message and run itself a script. the good news is it's pretty easy to remove/disable.
psyklone is offline   Reply With Quote
Old 05-22-2000, 04:48 PM   #4
Brydon
Ultimate Member
 
Brydon's Avatar
 
Join Date: Dec 1999
Location: Edinburgh, Scotland
Posts: 1,742
Thumbs up

Yep I heard about that one to but thanks for the reminder anyway Gene, always keep your virus definitions up to date .
Brydon is offline   Reply With Quote
Old 05-22-2000, 05:37 PM   #5
Darvocet
Member
 
Join Date: Apr 2000
Location: Knoxville TN USA
Posts: 136
Thumbs up

Gene,

This virus/worm struck back in Jan with limited effect but here is the info on it from Mcafee.com. No offense intended.

Virus Profile

Virus Name
WScript/Kak.worm

Date Added
12/31/99

Virus Characteristics
This worm was first discovered by AVERT in December and added detection for it within 4051 DAT updates. Virus Patrol, a newsgroup scanning program from NAI, continues to identify occurrences of this Internet worm in newsgroup postings which is an indication that worm is continuing to spread. AVERT recommends adding ".HTA" to file extensions scanned for protection, and also ensure users have installed the security patch from Microsoft mentioned below.

Another dangerous aspect of this Internet worm is the ability to continuously re-infect yourself if the preview pane is enabled and you browse between folders specifically the "sent" folder which happens to contain the Internet worm within a message. This is another strong reason to update to the security patch, if not already.*

This is an Internet worm which uses ActiveX and Windows Scripting Host to propagate itself through email using MS Outlook. This worm consists of 3 components, an HTA file (HTML for Applications), a REG file (Registration Entries Update) and a BAT file (MS-DOS Batch).

The method used to integrate these components is to have first composed an email message in HTML which supports scripting. Using an ActiveX exploit known as "Scriptlet TypeLib", the script writes an HTA file to the local machine, typically in the startup folder. This will launch the code embedded in the HTA file at the next Windows startup. Microsoft has published a security update which addresses this ActiveX exploit and users are encouraged to update their systems with this component. With this update installed, users are questioned if they wish to run the ActiveX control which is marked "safe for scripting".

For more details on this vulnerability and to obtain a patch from Microsoft, see this link:
Microsoft Security Bulletin

For current security bulletins from Microsoft, see this link:
Current Bulletins.

Email messages written in HTML format will be coded with the Internet worm on infected systems due to the default signature modification on infected systems. The email application Outlook is a target of this Internet worm for propagation due to its support for HTML format messages. If an email message is coded with the WScript/Kak.worm code and it is allowed to run, files are written to the local machine in different locations-

c:\windows\kak.htm
c:\windows\system\(name).hta

kak.hta is written to either folder:
French Windows
c:\windows\Menu Démarrer\Programmes\Démarrage\

English Windows
c:\windows\Start Menu\Programs\StartUp\

In the above list, "(name)" is a seemingly random 8 character name (e.g. 98278AE0.HTA) however it is related directly to a registry entry. The path name of "Démarrage" gives us an indication that its origin is France with target installations of French Windows 9x operating systems; the secondary path targets English installations.

This worm first copies the original AUTOEXEC.BAT file as AE.KAK. Then the AUTOEXEC.BAT file is modified to run the file KAK.HTA and then delete it from its folder location. The system registry is also modified when the script executes a shell registry update using regedit and the REG file written to the local system. The registry modification is this-

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
cAg0u = "C:\WINDOWS\SYSTEM\(name).hta"

The entry "(name)" is an 8 character name (e.g. 98278AE0.HTA).

The email spreading method is possible by a registry modification which adds a signature to MS Outlook. The signature is set to include the file "C:\WINDOWS\kak.htm" and is set as the default signature such that the worm is spread on all outgoing email if the signature is included.

The contents of the HTM file are just a small file which consists of script to run the KAK.HTA file which already exists on the target machine. The code looks specifically for browser versions IE5 or NetScape Navigator higher than v4.0. Finally this worm also has a payload which is date activated.

On the 1st of the month, and beginning from 6PM local time, a message is displayed:

"Kagou-Anti-Kro$oft says not today!"


--------------------------------------------------------------------------------

Send This Virus Information To A Friend?

--------------------------------------------------------------------------------

Indications Of Infection
Recipients of messages which contain Wscript/Kak.worm may receive warning messages such as:
"Do you want to allow software such as ActiveX controls and plug-ins to run?"

Users should select "NO" to this question. Also another warning dialogue box could be displayed:
"Scripts are usually safe. Do you want to allow scripts to run?"

Users should select "NO" also to this question. Further indications of infection are the existence of files KAK.HTA and KAK.HTM as mentioned above, registry modifications as mentioned above, added or modified default signature as mentioned above.

On the 1st of the month, and beginning from 6PM local time, a message is displayed:

"Kagou-Anti-Kro$oft says not today!"

Another possible message is a fake error message with this description:

"S3 driver memory alloc failed"

After this, Windows is instructed to shutdown.

Method Of Infection
Opening email messages which are composed in HTML format and which contain the script will install the Internet worm on supported systems as mentioned above. The HTA file is written to the local machine as is the HTM file and both are created at system startup, and with each composition of HTML format email message.

Removal of this Internet worm consists of several steps:

* close email client(s)
* install the MS patch mentioned above
* remove KAK.HTA and/or KAK.HTM
* turn off "preview pane"
* delete the default email signature
* delete messages which are not needed which may contain the embedded script

Users may also benefit by removing Windows Scripting Host from their Windows environment. To do this in Windows 9x, go to "Control Panel" and choose "Add/Remove Programs". Click on the "Windows Setup" tab and double click on "Accessories". Scroll down to "Windows Script Host" and uncheck it and choose "OK". It may be necessary to reboot the system. For additional help or support, visit Microsoft's Support Site.

Removal Instructions
Use specified engine and DAT files for detection and removal. Delete files found to contain this detection.


Virus Information
Discovery Date: 12/31/99
Origin: France
Type: Virus
SubType: VbScript
Risk Assessment: Medium


Aliases
JS/Kak.worm, Kagou-Anti-Kro$oft, Kak, VBS.Kak.Worm, VBS/Kak, Wscript.Kak, Wscript.KakWorm

Related Viruses
VBS/Bubbleboy

Minimum Dat
4051

Minimum Engine
4.0.25


Darvocet is offline   Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:41 AM.


  • Weekly CPU Prices for February 5, 2010
  • Weekly CPU Prices for January 29, 2010
  • Weekly CPU Prices for January 22, 2010
  • Weekly CPU Prices for January 15, 2010
  • Weekly CPU Prices for January 8, 2010
  • Weekly CPU Prices for December 31, 2009
  • Weekly CPU Prices for December 25, 2009
  • Weekly CPU Prices for December 18, 2009




    IBM Power7: Big Blue's Answer to Oracle, Intel
    Chip Stocks Stabilize as Market Fall Continues
    Mozilla Firefox to Drop Support of Mac OS X 10.4
    SAP's CEO Ouster Latest Indication of Troubles
    Oracle Adds SOA Depth with AmberPoint Deal
    Cisco Aims to Simplify Datacenter Migrations
    Google Earns High Marks for Super Bowl Ad
    Investors Unimpressed With NetSuite's Q4
    Facebook Says Adios to Microsoft Banner Ads
    Why Red Hat Had to Pull the Plug on Exchange


  • Acceptable Use Policy


    The Network for Technology Professionals

    Search:

    About Internet.com

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | E-mail Offers


    Powered by vBulletin® Version 3.7.3
    Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
    Copyright 2002 Jupitermedia Corporation